Playcall privacy
Last updated July 23, 2026.
Playcall reads the business data you connect and turns it into a working board: tasks, a morning brief, and reviews. This page says exactly what is read, what is stored, and what never leaves. If anything here changes, this page changes first.
Signing in
You sign in with Google. Playcall receives your email address and stores it with an account id derived from it. Playcall never sees your Google password, and sign-in on its own grants no access to your mail, calendar, or files.
What each connected stream reads
Every stream is optional, connected by you, and read-only. Playcall never writes to, sends from, or changes anything in a connected account.
- Gmail. Read-only. Playcall reads message headers (sender, subject, dates) from your inbox and Sent mail from the last 14 days. The text of recent messages from real people is read by an automated classifier whose only output is a category and an urgency; message text is never stored, never shown to anyone, and never used to write board content. Attachments are never opened. Playcall cannot send, delete, or label mail: the access scope Google grants does not allow it.
- Google Calendar. Read-only. Playcall reads your calendar list and events on the calendars you keep selected, from the last 7 days and the next 7: times, titles, and whether guests are invited. It stores derived numbers (booked hours, open hours, event counts), not your events.
- Stripe. Read-only, via a restricted key you create. Playcall reads balances, charges, and subscription state and stores derived revenue numbers.
- Google Analytics and Search Console. Read-only aggregate traffic and search numbers for the one property you share.
- GitHub. Read-only activity on the one repository you pick: commit counts and recency, not code.
- Reddit. Public threads matching keywords you choose. Playcall never posts.
- Linear. Read-only issues for the one team you pick.
- Discord. Messages in the specific channels you pick on your own server, to surface community questions. Never direct messages.
How credentials are kept
Connection credentials (tokens, keys, app passwords) are encrypted at rest, are never shown back to you or anyone else, and travel only to the provider they belong to. Disconnecting a stream deletes its credential the same moment.
AI processing
Playcall's judgment runs on Anthropic's Claude models. Derived business signals (counts, amounts, capped subject lines from your inbox) are sent to Anthropic's API to draft your tasks and briefs. Anthropic does not train on this API traffic under its commercial terms.
Google API disclosure
Playcall's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never used for advertising, never sold or transferred to data brokers, and never used to create, train, or improve generalized AI or machine learning models.
Your data
Your board, signals, and settings belong to you. You can export them or erase them from Settings at any time; erasing removes your stored data and credentials from the server. Questions or removal requests: team@getmoonbounce.com.